VistaKing
New member
Hi Vistaking
Let me explain to you regarding ransomwares.Ransomware hooks entries in multiple locations.Winlogon and Run keys.Fixing both the keys using recovery console method will fail and user will just have a white screen because the ransomware is active.
If the user can't get into save mode the programs you're mentioning is useless .
Wrong.How did user try the system restore or access MSCONFIG in his previous steps?
Safemode with command prompt gives us a command window.Flash drive can be accessed and any security tools can be used to scan our system without launching the explorer window.
Safemode with command prompt or FRST are best way to fix it.Launching registry in recovery console is time consuming.
Shawn you don't have to explain anything for me. Trust me I know what I am doing. I am not going to argue with you. The reason why she or he isn't allowed to get on to explorer.exe is cause the virus is starting it from when the PC starts up. IF you go to the registry and change the shell from what is on there to explorer.exe he or she will be able to get into safe mode and safe mode with networking. You have a matter of seconds until the virus loads up.
For a user to get to his flash drive he or she would have to know the drive letter of his flash drive.
That is why when I had the user do bcdedit | find "osdevice" it pointed to D .
My Computer
- Computer Manufacturer/Model Number
- Custom Built
- OS
- Windows 7 Ultimate 32-Bit & Windows 7 Ultimate 64-Bit
- CPU
- Intel Core i7 CPU 950 @ 3.07GHz
- Motherboard
- ASUS P6T DELUXE V2
- Memory
- OCZ 6GB (3 x 2GB) 240-Pin DDR3 SDRAM DDR3 1600 OCZ3X1600R2
- Graphics Card(s)
- ATI Radeon HD 5700 Series
- Sound Card
- OnBoard
- Hard Drives
- WD6400AACS-00M3B0 (640GB SATA )
- PSU
- CORSAIR 850w
- Case
- NZXT LEXA
- Cooling
- Intel Stock Heatsink Fan
- Keyboard
- Microsoft Wireless Laser Keyboard 7000
- Mouse
- Microsoft Wireless Laser Mouse 7000
